Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-1787 — LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Co…

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' funct…

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.8 MEDIUM
CVE-2026-27576 — OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsivenes…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.se…

openclaw | Denial of Service
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.3 HIGH
CVE-2026-27488 — OpenClaw hardened cron webhook delivery against SSRF

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal…

openclaw | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.0 HIGH
CVE-2026-27487 — OpenClaw: Prevent shell injection in macOS keychain credential write

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into…

macos openclaw | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-27486 — OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without …

openclaw | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
4.6 MEDIUM
CVE-2026-27485 — OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in in…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlin…

openclaw | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.3 MEDIUM
CVE-2026-27484 — OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven f…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, in…

openclaw | Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27482 — Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdo…

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. …

ray | Remote | Authentication
Feb 21, 2026 Mar 04, 2026
Feb 21, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-27480 — Static Web Server: Timing-Based Username Enumeration in Basic Authentication

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authenti…

static_web_server | Remote | Authentication
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2025-14339 — weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and …

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.7 HIGH
CVE-2026-27479 — Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon up…

wallos | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-2865 — itsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php …

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler.…

Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-2864 — feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path trave…

A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the function pictureDelete of the file PictureController.j…

Remote | Path Traversal
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-27470 — ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cau…

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the …

zoneminder | Remote | Injection
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27469 — Isso: Stored XSS via comment website field

Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affect…

Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
2.4 LOW
CVE-2026-27467 — BigBlueButton: Audio from participants to the server initially unmuted

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state.…

bigbluebutton | Remote | Information Disclosure
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-27466 — BigBlueButton: Exposed ClamAV port enables Denial of Service

BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains inst…

bigbluebutton | Remote | Denial of Service
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.7 HIGH
CVE-2026-27464 — Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE

Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase ins…

metabase | Remote | Information Disclosure
Feb 21, 2026 Mar 02, 2026
Feb 21, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-27471 — ERP: Document access through endpoints due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorize…

erpnext | Remote | Authorization
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
8.7 HIGH
CVE-2026-27458 — LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authent…

linkace | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
Showing 20 of 5516 Results